> Markdown version of [/jobs/ext/1996927-information-security-compiance-officer](https://www.wearedevelopers.com/jobs/ext/1996927-information-security-compiance-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security & Compiance Officer - **Company:** Billit - **Location:** Gent, Belgium - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software as a Service, Cyber Security - **Published:** August 9, 2026 - **Apply:** https://www.careerjet.be/jobad/bea461da735861c0b9b67f5d898fb7657f ## About the Role * You have at least a few years of relevant experience in an operational compliance or security role, preferably in a regulated environment (fintech, SaaS, healthcare, government…). * Ideally, you're already familiar with DORA, ISO 27001, and/or GDPR. * Relevant certifications (ISO 27001 Lead Implementer, CISM, CRISC…) are a real asset, though not required. * You preferably have demonstrable experience managing security documentation and supporting audits. If you don't have that specific experience yet but bring strong analytical thinking, drive, and a hunger to learn fast - don't let that stop you from applying. * You communicate fluently in English and preferably also in Dutch. ## Description Are you our pragmatic link between compliance and the day-to-day? As a fintech SaaS company, Billit operates in a heavily regulated environment - think DORA and ISO 27001. That's why we're expanding our team with someone who: * operationally translates our security and compliance obligations into day-to-day practice * and makes good governance real and workable in a scale-up that takes quality seriously - without turning it into bureaucratic overhead. What does an Information Security & Compliance Officer do at Billit? You're the operational engine behind our security and compliance work. You coordinate, document, and monitor processes. You make sure that what's written on paper is actually followed and acted upon. You report to our Chief Quality Officer and serve as the bridge between strategy and execution. In practice: * You coordinate and follow up on incoming security reports, making sure they reach the right teams on time. * You monitor SLA's, follow-up deadlines, and the progress of security cases. * You manage our ISO 27001 documentation and ensure the quality, completeness, and consistency of all security and audit information. * You coordinate internal and external penetration tests, including planning, communication, and administrative follow-up. * You serve as the first point of contact for general security and compliance questions - both internally and externally. * You follow up on scan results and ensure findings are properly registered and handled. * You report on open findings, KPIs, and remediation progress. * You support audits and compliance activities and actively contribute to the continuous improvement of our security processes. * You optimize and document operational security processes and work instructions - pragmatically and scalably. * For those familiar with the Three Lines of Defense model: you work within our 1st line of control quality team. On the front line, hands-on and boots on the ground. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)